USENIX Security2026Top-tier venue
TrioFuzz: A Three-Tier Architecture for Adaptive Strategy Selection in Fuzzing
Ruiqi Dong, Yiyi Wang, Kunpeng Zhang, Dongsong Yu, Xiaogang Zhu, Shaohua Wang, Shuai Wang, Chao Zhang, Sheng Wen, Yang Xiang
Abstract
Adaptive strategy selection is a promising direction for improving fuzzing effectiveness, yet existing learning-based approaches often fail to outperform random selection in practice. We identify the root cause as an architectural mismatch rather than an algorithmic limitation. Our empirical study reveals that strategy effectiveness shifts at minute-level timescales, while existing in-loop architectures require tens of minutes per learning cycle. This order-of-magnitude gap prevents timely adaptation regardless of which learning algorithm is used.
We propose TRIOFUZZ, a new fuzzing engine that decouples learning from execution through a three-tier thread architecture. A centralized learning thread aggregates feedback from parallel execution threads, compressing the adaptation cycle to under one minute. TRIOFUZZ integrates the same learning algorithms as prior work, isolating the architectural contribution from algorithmic factors. Our ablation study shows that learning algorithms perform significantly better under our proposed architecture than under their original inloop implementations. Notably, native MOpt underperforms baselines, but becomes a competitive performer under TRIO-FUZZ's architecture. Evaluation on FuzzBench and OSS-Fuzz shows that TRIOFUZZ achieves the highest coverage on 7 out of 9 FuzzBench targets and 8 out of 10 OSS-Fuzz projects, triggers 17% more vulnerabilities than AFL++ on Magma, and discovers 19 new CVEs in 6 real-world projects.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu et al.S&P 2018 · 426 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
Related papers
- SimiFuzz: Seed–Worker Scheduling for Parallel Fuzzing via Contextual BanditsYijia Guo, Zhiguo Ding, Hong Liang, Ming Zhong et al.ISSTA 2026
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 139 citations
- MUZZ: Thread-aware Grey-box Fuzzing for Effective Bug Hunting in Multithreaded ProgramsHongxu Chen, Shengjian Guo, Yinxing Xue, Yulei Sui et al.USENIX Security 2020
- µFUZZ: Redesign of Parallel Fuzzing using Microservice ArchitectureYongheng Chen, Rui Zhong, Yupeng Yang, Hong Hu et al.USENIX Security 2023
- xFUZZ: A Flexible Framework for Fine-Grained, Runtime-Adaptive Fuzzing Strategy CompositionDongsong Yu, Yiyi Wang, Chao Zhang, Yang Lan et al.ISSTA 2025
